SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.20Addressing information security within supplier agreements

Write relevant security requirements into supplier contracts so expectations are clear and enforceable. Spell out responsibilities before problems arise, not after.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

In practice

In practice this is a contract clause library: standard security and data protection language legal or procurement pulls into every supplier agreement rather than negotiating from scratch each time. Auditors ask to see a sample contract from a supplier handling sensitive data and check whether the clauses made it into the signed document, not only the vendor's proposed terms. The common failure is a company with good clause language sitting in a template but never inserted into contracts signed before procurement adopted the template, leaving older, still-active suppliers uncovered.

Common gaps

Security clauses exist in the standard contract template, but several active supplier contracts predate the template and were never amended to include them.
The contract includes a right-to-audit clause, but it has never been exercised against any supplier since signing.
Breach notification terms in the contract do not specify a timeframe, leaving a vague promise as the only obligation on a supplier with real access to customer data.

Questions your auditor will ask

What security requirements are written into your supplier contracts?
Point to the standard clause set covering breach notification, data protection terms and audit rights, then show it present in a signed contract with a data-handling supplier.
Do older supplier contracts include the same protections as new ones?
Identify any contracts signed before the current clause template was adopted, and describe the plan or timeline for bringing them up to the same standard.
How do you know if a supplier is meeting the security obligations in their contract?
Show the tracking process that checks stated obligations against supplier behaviour and the escalation path for non-compliance.

Where regulation demands it

NIS2 art. 5.1 (Supply chain security policy) requires the same contractual approach A.5.20 asks organizations to take with suppliers.
ENS op.ext.1 (Contratación y acuerdos de nivel de servicio) is the equivalent baseline for security terms in service agreements.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.20?”
Also via MCP, free with account